IP Library › Granted Patent US 12,333,382
Granted Patent B2
US 12,333,382 · App. 18/111,413 · Granted Jun 17, 2025

Quantum circuit optimization using windowed quantum arithmetic

Inventor: Craig Gidney (Goleta, CA)
Assignee: Google LLC
G06N10/20G06F7/4824G06F7/505G06F7/5057G06F7/72G06F17/10G06N10/00G06N10/70G11C11/4063H04B10/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,333,382
App. No.
18/111,413
Granted
Jun 17, 2025
Kind
B2
Abstract

Methods, systems and apparatus for performing windowed quantum arithmetic. In one aspect, a method for performing a product addition operation includes: determining multiple entries of a lookup table, comprising, for each index in a first set of indices, multiplying the index value by a scalar for the product addition operation; for each index in a second set of indices, determining multiple address values, comprising extracting source register values corresponding to indices between i) the index in the second set of indices, and ii) the index in the second set of indices plus the predetermined window size; and adjusting values of a target quantum register based on the determined multiple entries of the lookup table and the determined multiple address values.

Claims (51)

1. A method for performing a modular exponentiation operation using a target quantum register of qubits and a source quantum register of qubits, the method comprising:

for each index in a first set of indices,

determining a first plurality of address values, comprising extracting multiple source register values;

for each index in a second set of indices,

determining a second plurality of address values, comprising extracting multiple target register values;

for each index in a third set of indices and for each index in a fourth set of indices,

determining a table entry by multiplying i) the index in the third set of indices, ii) the index in the fourth set of indices, and iii) 2 to the power of the index in the second set of indices, and applying a modulus operation;

adjusting a modular addition register using table entries corresponding to the first plurality of address values and the second plurality of address values;

for each index in a fifth set of indices,

determining a third plurality of address values, comprising extracting multiple values of the adjusted modular addition register;

determining, for each index in a sixth set of indices, multiple table entries, the determining comprising, for each index in a seventh set of indices,

determining a table entry that corresponds to the index in the seventh set of indices by multiplying i) the index in the sixth set of indices, ii) the index in the seventh set of indices, and iii) 2 to the power of the index in the fifth set of indices, and applying a modulus operation; and

adjusting the target quantum register using table entries corresponding to the first plurality of address values and the third plurality of address values.

2. The method of claim 1 , wherein the first set of indices comprises index values between zero and a first maximum index value that is a function of the source quantum register, wherein the index values are stepped by a first predetermined window size.

3. The method of claim 1 , wherein the second set of indices comprises index values between zero and a second maximum index value that is a function of the target register, wherein the index values are stepped by a second predetermined window size.

4. The method of claim 2 , wherein the third set of indices comprises index values between 1 and a third maximum value that is based on the first predetermined window size.

5. The method of claim 3 , wherein the fourth set of indices comprises index values between 0 and a fourth maximum value that is a function of the target quantum register and the second predetermined window size.

6. The method of claim 3 , wherein the fifth set of indices comprises index values between zero and a fifth maximum index value that is a function of the target register, wherein the index values are stepped by the second predetermined window size.

7. The method of claim 3 , wherein the sixth set of indices comprises index values between 1 and a sixth value that is based on the second predetermined window size.

8. The method of claim 3 , wherein the seventh set of indices comprises index values between 0 and a seventh maximum value that is a function of the modular addition register and the second predetermined window size.

9. The method of claim 2 , wherein determining the first plurality of address values comprises extracting source register values corresponding to indices between i) the index in the first set of indices, and ii) the index in the first set of indices plus the first predetermined window size.

10. The method of claim 3 , wherein determining the second plurality of address values comprises extracting target register values corresponding to indices between i) the index in the second set of indices, and ii) the index in the second set of indices plus the second predetermined window size.

11. The method of claim 3 , wherein determining the third plurality of address values comprises extracting values of the adjusted modular addition register corresponding to indices between i) the index in the fifth set of indices, and ii) the index in the fifth set of indices plus the second predetermined window size.

12. The method of claim 2 , wherein the first maximum index value that is a function of the source quantum register is equal to the length of the source quantum register.

13. The method of claim 3 , wherein the second maximum index value that is a function of the target register is equal to the length of the target quantum register.

14. The method of claim 4 , wherein the third maximum value that is based on the first predetermined window size comprises k 2i+w 1 where k represents a scalar for the modular exponentiation operation, i represents the index in the first set of indices, and w 1 represents the first predetermined window size.

15. The method of claim 5 , wherein the fourth maximum value that is a function of the target quantum register and the second predetermined window size comprises 2 to the power of the second window size.

16. The method of claim 6 , wherein the fifth maximum index value that is a function of the target register is equal to the length of the target quantum register.

17. The method of claim 8 , wherein the seventh maximum value that is a function of the target quantum register and the second predetermined window size comprises 2 to the power of the second window size.

18. The method of claim 1 , wherein the modular exponentiation operation performs x*=k e (mod N), where x represents a variable storing a first value in the target quantum register, e represents a corresponding variable storing a second value in the source quantum register, k represents a classical constant scalar value for the modular exponentiation operation, and N represent a classical constant modulo for the modular exponentiation operation.

19. The method of claim 18 , wherein the first value comprises a classical integer or a superposition of classical integers and wherein the second value comprises a classical integer or a superposition of classical integers.

20. The method of claim 2 , wherein

the second set of indices comprises index values between zero and a second maximum index value that is a function of the target register, wherein the index values are stepped by a second predetermined window size, and

the first predetermined window size and the second predetermined window size are equal.

21. The method of claim 20 , wherein the first predetermined window size and second predetermined window size are equal to ln n/2, where n represents a number of logical qubits in the target quantum register.

22. An apparatus comprising:

one or more classical computing processors; and

quantum computing hardware in data communication with the one or more classical processors,

wherein the apparatus is configured to perform operations for performing a modular exponentiation operation using a target quantum register of qubits and a source quantum register of qubits, the operations comprising:

for each index in a first set of indices,

determining a first plurality of address values, comprising extracting multiple source register values;

for each index in a second set of indices,

determining a second plurality of address values, comprising extracting multiple target register values;

for each index in a third set of indices and for each index in a fourth set of indices,

 determining a table entry by multiplying i) the index in the third set of indices, ii) the index in the fourth set of indices, and iii) 2 to the power of the index in the second set of indices, and applying a modulus operation;

adjusting a modular addition register using table entries corresponding to the first plurality of address values and the second plurality of address values;

for each index in a fifth set of indices,

determining a third plurality of address values, comprising extracting multiple values of the adjusted modular addition register;

determining, for each index in a sixth set of indices, multiple table entries, the determining comprising, for each index in a seventh set of indices,

 determining a table entry that corresponds to the index in the seventh set of indices by multiplying i) the index in the sixth set of indices, ii) the index in the seventh set of indices, and iii) 2 to the power of the index in the fifth set of indices, and applying a modulus operation; and

adjusting the target quantum register using table entries corresponding to the first plurality of address values and the third plurality of address values.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2023
From: GIDNEY, CRAIG
To: GOOGLE LLC
Reel/Frame 065215/0628 →
Continuity (3)
Division 16833250 · Mar 27, 2020
Provisional Application 62826142 · Mar 29, 2019
Related Publication 20230281497A1 · Sep 7, 2023
References Cited (122)
US 10505524B1 · Cohen · 2019 [cited by examiner]
US 20130311532A1 · Olsen · 2013 [cited by applicant]
US 20180113708A1 · Corbal et al. · 2018 [cited by applicant]
US 20180240032A1 · Rooyen · 2018 [cited by applicant]
US 20190042971A1 · Zou · 2019 [cited by applicant]
US 20200311592A1 · Gidney · 2020 [cited by examiner]
US 20220084123A1 · Ramesh · 2022 [cited by examiner]
US 20220147266A1 · Hann · 2022 [cited by examiner]
US 20220374378A1 · Sivan · 2022 [cited by examiner]
US 20230026518A1 · Burchard · 2023 [cited by examiner]
US 20230229950A1 · Selly · 2023 [cited by examiner]
CN 107683460 · 2018 [cited by applicant]
WO WO2020205612 · 2020 [cited by applicant]
Notice of Allowance in Australian Appln. No. 2022275474, mailed on Dec. 7, 2023, 3 pages. [cited by applicant]
Alagic et al., “Status Report on the First Round of the NIST Post-Quantum Cryptography Standardization Process,” Tech. Rep., National Institute of Standards and Technology, Jan. 2019, 27 pages. [cited by applicant]
Apps.nsa.gov [online], “CNSA Suite and Quantum Computing FAQ,” retrieved from URL <https://apps.nsa.gov/iaarchive/library/ia-guidance/ia-solutions-for-classified/algorithm-guidance/cnsa-suite-and-quantum-computing-faq.c… [cited by applicant]
Babbush et al., “Encoding Electronic Spectra in Quantum Circuits with Linear T Complexity,” Physical Review X, Oct. 2018, 041015-1-041015-36. [cited by applicant]
Barends et al., “Superconducting quantum circuits at the surface code threshold for fault tolerance,” Nature, Apr. 2014, 508:500-503. [cited by applicant]
Beauregard, “Circuit for Shor's algorithm using 2n+3 qubits,” https://arxiv.org/abs/quant-ph/0205095v1, May 2002, 13 pages. [cited by applicant]
Berry et al., “Qubitization of Arbitrary Basis Quantum Chemistry by Low Rank Factorization,” Submitted on Feb. 2019, arXiv:1902.02134v1, 20 pages. [cited by applicant]
Bocharov et al., “Efficient Synthesis of Universal Repeat-Until-Success Circuits,” Submitted on Apr. 2014, arXiv:1404.5320v1, 16 pages. [cited by applicant]
Braithwaite, “Experimenting with Post-Quantum Cryptography,” retrieved from URL <https://security.googleblog.com/2016/07/experimenting-with-post-quantum.html>, Jul. 2016, 5 pages. [cited by applicant]
Bravyi et al., “Universal quantum computation with ideal Clifford gates and noisy ancillas,” Physical Review A, Feb. 2005, 71:022316-1-022316-14. [cited by applicant]
Buhler et al., “Factoring integers with the number field sieve,” in The Development of the No. Field Sieve, Lecture Notes in Mathematics (LNM), 1993, 1554:50-94. [cited by applicant]
Campbell et al., “Applying quantum algorithms to constraint satisfaction problems,” Submitted on Oct. 2018, arXiv:1810.05582v1, 26 pages. [cited by applicant]
Cuccaro et al., “A new quantum ripple-carry addition circuit,” https://arxiv.org/abs/quant-ph/0410184, Oct. 2004, 9 pages. [cited by applicant]
De Beaudrap et al., “The ZX calculus is a language for surface code lattice surgery,” Submitted on Apr. 2017, arXiv:1704.08670v1, 19 pages. [cited by applicant]
Diffie et al., “New Directions in Cryptography,” IEEE Transactions on Information Theory, Nov. 1976, 22(6):644-654. [cited by applicant]
Draper et al., “A logarithmic-depth quantum carry-lookahead adder,” https://arxiv.org/abs/quant-ph/0406142, Jun. 2004, 21 pages. [cited by applicant]
Eastin, “Distilling one-qubit magic states into Toffoli states,” Physical Review A, Mar. 2013, 87:032321-1-032321-7. [cited by applicant]
Ekera et al., “Quantum Algorithms for Computing Short Discrete Logarithms and Factoring RSA Integers,” International Workshop on Post-Quantum Cryptography, Jun. 2017, 347-363. [cited by applicant]
Ekera, “Modifying Shor's algorithm to compute short discrete logarithms,” retrieved from URL <https://eprint.iacr.org/2016/1128.pdf>, Dec. 2016, 26 pages. [cited by applicant]
Ekera, “On post-processing in the quantum algorithm for computing short discrete logarithms,” retrieved from URL <https://eprint.iacr.org/2017/1122.pdf>, Feb. 2019, 19 pages. [cited by applicant]
Ekera, “Quantum algorithms for computing general discrete logarithms and orders with tradeoffs,” retrieved from URL <https://eprint.iacr.org/2018/797.pdf>, Mar. 2020, 52 pages. [cited by applicant]
Ekera, “Revisiting Shor's quantum algorithm for computing general discrete logarithms,” Submitted on May 2019, arXiv:1905.09084, 13 pages. [cited by applicant]
Fowler et al., “A bridge to lower overhead quantum computation,” Submitted on Sep. 2012, arXiv:1209.0510v1, 15 pages. [cited by applicant]
Fowler et al., “Low overhead quantum computation using lattice surgery,” Submitted on Aug. 2018, arXiv:1808.06709v1, 15 pages. [cited by applicant]
Fowler et al., “Surface codes: Towards practical large-scale quantum computation,” Physical Review A, Sep. 2012, 86:032324-1-032324-48. [cited by applicant]
Fowler et al., “Surface code implementation of block code state distillation,” Scientific Reports, Jun. 2013, 3(1939):1-6. [cited by applicant]
Fowler, “Time-optimal quantum computation,” Submitted on Oct. 2012, arXiv:1210.4626v1, 5 pages. [cited by applicant]
Gheorghiu et al., “Quantum cryptanalysis of symmetric, public-key and hash-based cryptographic schemes,” Submitted on Feb. 2019, arXiv:1902.02332v1, 19 pages. [cited by applicant]
Gidney et al., “Efficient magic state factories with a catalyzed |CCZ> to 2|T> transformation,” Submitted on Dec. 2018, arXiv:1812.01238v1, 24 pages. [cited by applicant]
Gidney et al., “How to factor 2048 bit RSA integers in 7 hours using 23 million noisy qubits,” Submitted on Dec. 2019, arXiv:1905.09749, 26 pages. [cited by applicant]
Gidney et al., “How to factor 2048 bit RSA integers in 7 hours using 23 million noisy qubits,” Submitted on May 2019, arXiv:1905.09749v1, 25 pages. [cited by applicant]
Gidney et al., “Efficient magic state factories with a catalyzed |CCZ> to 2|T> transformation,” Submitted on Apr. 2019, arXiv:1812.01238v3, 24 pages. [cited by applicant]
Gidney et al., “Flexible layout of surface code computations using AutoCCZ states,” Submitted on May 2019, arXiv:1905.08916, 17 pages. [cited by applicant]
Gidney, “Factoring with n+2 clean qubits and n-1 dirty qubits” Submitted on Jun. 2017, arXiv: 1706.07884v1, 13 pages. [cited by applicant]
Gidney, “Halving the cost of quantum addition,” Quantum 2, Jun. 2018, 6 pages. [cited by applicant]
Gidney, “Approximate encoded permutations and piecewise quantum adders,” Submitted on May 2019, arXiv:1905.08488, 15 pages. [cited by applicant]
Gidney, “Asymptotically Efficient Quantum Karatsuba Multiplication,” Submitted on Apr. 2019, arXiv:1904.07356, 11 pages. [cited by applicant]
Gidney, “Windowed quantum arithmetic,” Submitted on May 2019, arXiv:1905.07682, 11 pages. [cited by applicant]
Gillmor, “RFC 7919: Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS),” retrieved from URL <https://www.hjp.at/doc/rfc/rfc7919.html>, Aug. 2016, 30 pages. [cited by applicant]
Github.com [online], “OpenSSL Software Foundation, Openssl source code: Line 32 of apps/dhparam.c,” retrieved from URL <https://github.com/openssl/openssl/blob/07f434441e7ea385f975e8df8caa03e62222ca61/apps/dhparam.c#L32… [cited by applicant]
Github.com [online], “Quirk: A drag-and-drop quantum circuit simulator for exploring small quantum circuits,” available on or before Jun. 11, 2018, via Internet Archive: Wayback Machine URL <https://web.archive.org/web/… [cited by applicant]
Gnupg.org [online], “GnuPG frequently asked questions—11.2 Why Does GnuPG Default to 2048 bit RSA-2048?” available on or before Jul. 1, 2016, via Internet Archive: Wayback Machine URL <https://web.archive.org/web/201607… [cited by applicant]
Gordon, “Discrete logarithms in GF(p) using the Number Field Sieve,” SIAM Journal on Discrete Mathematics, 1993, 6:124-138. [cited by applicant]
Gottesman et al., “Demonstrating the viability of universal quantum computation using teleportation and single-qubit operations,” Nature, Nov. 1999, 402:390-393. [cited by applicant]
Gottesman, “The Heisenberg Representation of Quantum Computers,” https://arxiv.org/abs/quant-ph/9807006, Jul. 1998, 20 pages. [cited by applicant]
Griffiths et al., “Semiclassical Fourier Transform for Quantum Computation,” Physical Review Letters, Apr. 1996, 76(17):3228-3231. [cited by applicant]
Haah et al., “Codes and Protocols for Distilling T, controlled-S, and Toffoli Gates,” Quantum 2, retrieved from URL <https://arxiv.org/abs/1709.02832v3>, May 2018, 29 pages. [cited by applicant]
Haner et al., “Factoring using 2n+2 qubits with Toffoli based modular multiplication,” Submitted on Nov. 2016, arXiv:1611.07995v1, 7 pages. [cited by applicant]
Hastings et al., “Reduced Space-Time and Time Costs Using Dislocation Codes and Arbitrary Ancillas,” Submitted on Aug. 2014, arXiv:1408.3379v1, 16 pages. [cited by applicant]
Horsman et al., “Surface code quantum computing by lattice surgery,” New Journal of Physics, Dec. 2012, 28 pages. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2020/025445, dated Oct. 14, 2021, 17 pages. [cited by applicant]
Jeandel et al., “A Complete Axiomatisation of the ZX-Calculus for Clifford+T Quantum Mechanics,” Proceedings of the 33rd Annual ACM/IEEE Symposium on Logic in Computer Science, Jul. 2018, 10 pages. [cited by applicant]
Jones, “Low-overhead constructions for the fault-tolerant Toffoli gate,” Physical Review A, Feb. 2013, 022328-1-022328-4. [cited by applicant]
Karatsuba et al., “Multiplication of many-digital numbers by automatic computers,” Doklady Akademii Nauk, Russian Academy of Sciences, Feb. 1962, 145(2):293-294 (with English translation). [cited by applicant]
Keylength.com [online], “BlueKrypt—Cryptographic Key Length Recommendation,” available on or before Mar. 3, 2019, via Internet Archive: Wayback Machine URL <https://web.archive.org/web/20190303042857/https://www.keyleng… [cited by applicant]
Kim et al., “Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors,” 2014 ACM/IEEE 41st International Symposium on Computer Architecture (ISCA), Jun. 2014, 12 pages. [cited by applicant]
Kitaev, “Fault-tolerant quantum computation by anyons,” Annals of Physics, Jan. 2003, 303(1):2-30. [cited by applicant]
Kivinen et al., “RFC 3526: More Modular Exponentiation (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE),” retrieved from URL <https://www.hjp.at/doc/rfc/rfc3526.html>, May 2003, 11 pages. [cited by applicant]
Kleinjung et al., “Factorization of a 768-Bit RSA Modulus,” Lecture Notes in Computer Science: Advanced in Cryptology: Crypto 2010, 2010, 6223:333-350. [cited by applicant]
Lenstra et al., “Selecting Cryptographic Key Sizes,” Journal of Cryptology, 2001, 14:225-293. [cited by applicant]
Lenstra et al., “The number field sieve,” Proceedings of the 22nd Annual ACM Symposium on the Theory of Computing (STOC), 1990, 564-572. [cited by applicant]
Lenstra, “Key Lengths,” The Handbook of Information Security, retrieved from URL <http://citeseerx.ist.psu.edu/viewdoc/download;jsessionid=F4B43E1DEB9BD699C0F03EA08A2AD810?doi=10.1.1.694.8206&rep=rep1&type=pdf>, 2004, 3… [cited by applicant]
Li, “A magic state's fidelity can be superior to the operations that created it,” New Journal of Physics, Feb. 2015, 17:1-7. [cited by applicant]
Linux.die.net [online], “ssh-keygen(1)—Linux man page,” available on or before Mar. 25, 2018, via Internet Archive: Wayback Machine URL <https://web.archive.org/web/20180325042106/https://linux.die.net/man/1/ssh-keygen>… [cited by applicant]
Listserv.nodak.edu [online], “795-bit factoring and discrete logarithms,” retrieved from URL <https://listserv.nodak.edu/cgi-bin/wa.exe?A2=NMBRTHRY;fd743373.1912&FT=M&P=T&H=&S=>, Dec. 2, 2019, 2 pages. [cited by applicant]
Litinski, “A Game of Surface Codes: Large-Scale Quantum Computing with Lattice Surgery,” Submitted on Aug. 2018, arXiv:1808.02892v1, 35 pages. [cited by applicant]
Litinski, “Magic State Distillation: Not as Costly as You Think,” Submitted on May 2019, arXiv:1905.06903v1, 20 pages. [cited by applicant]
Low et al., “Trading T-gates for dirty qubits in state preparation and unitary synthesis,” Submitted on Dec. 2018, arXiv:1812.00954, 11 pages. [cited by applicant]
Mosca et al., “The Hidden Subgroup Problem and Eigenvalue Estimation on a Quantum Computer,” Proceeding from the First NASA International Conference: Quantum Computing and Quantum Communications (QCQC1998), May 1999, 15… [cited by applicant]
Mosca, “Cybersecurity in an Era with Quantum Computers: Will We Be Ready?” IEEE Security & Privacy, Oct. 2018, 16(5): 38-41. [cited by applicant]
NIST and CCCS, “Implementation Guidance for FIPS 140-2 and the Cryptographic Module Validation Program,” retrieved from URL <https://web.archive.org/web/20190313055345/https://csrc.nist.gov/csrc/media/projects/cryptogra… [cited by applicant]
NIST, “Recommendation for Key Management, Part 1: General (SP 800-57 Part 1 Rev. 4),” retrieved from URL <https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r4.pdf>, Jan. 2016, 161 pages. [cited by applicant]
NIST, “Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography (SP 800-56A Rev. 3),” retrieved from URL <https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf>,… [cited by applicant]
NIST, “Digital Signature Standard (DSS) (FIPS PUB 186-4),” retrieved from URL <https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf>, Jul. 2013, 130 pages. [cited by applicant]
Office Action in Australian Appln. No. 2020256115, dated Jun. 27, 2022, 5 pages. [cited by applicant]
Office Action in Australian Appln. No. 2022275474, dated May 26, 2023, 4 pages. [cited by applicant]
Office Action in Canadian Appln. No. 3135491, dated Jan. 3, 2023, 6 pages. [cited by applicant]
Office Action in Chinese Appln. No. 202080025632.7, dated May 25, 2022, 16 pages (with English translation). [cited by applicant]
Office Action in European Appln. No. 20721929.6, dated Oct. 5, 2022, 9 pages. [cited by applicant]
O'Gorman et al., “Quantum computation with realistic magic-state factories,” Physical Review A, Mar. 2017, 032338-1-032338-19. [cited by applicant]
Parent et al., “Improved reversible and quantum circuits for Karatsuba-based integer multiplication,” Submitted on Jun. 2017, arXiv:1706.03419, 16 pages. [cited by applicant]
Parker et al., “Efficient Factorization with a Single Pure Qubit and log N Mixed Qubits,” Physical Review Letters, Oct. 2000, 85(14):3049-3052. [cited by applicant]
PCT International Search Report and Written Opinion in International Appln. No. PCT/US2020/025445, mailed Aug. 12, 2020, 23 pages. [cited by applicant]
Pohlig et al., “An Improved Algorithm for Computing Logarithms over GF(p) and Its Cryptographic Significance,” IEEE Transactions on Information Theory, Jan. 1978, 24(1): 106-110. [cited by applicant]
Pollard, “Factoring with cubic integers,” Lecture Notes in Mathematics: The Development of the Number Field Sieve, Oct. 2006, 4-10. [cited by applicant]
Pollard, “Monte Carlo Methods for Index Computation (mod p),” Mathematics of Computation, Jul. 1978, 32(143):918-924. [cited by applicant]
Pollard, “The lattice sieve,” The Development of the Number Field Sieve, Lecture Notes in Mathematics (LNM), 1993, 1554:43-49. [cited by applicant]
Pomerance, “A Tale of Two Sieves,” Notices of the AMS, Dec. 1996, 43(12):1473-1485. [cited by applicant]
Raussendorf et al., “A fault-tolerant one-way quantum computer,” Annals of Physics, Sep. 2006, 321(9):2242-2270. [cited by applicant]
Raussendorf et al., “Fault-Tolerant Quantum Computation with High Threshold in Two Dimensions,” Physical Review Letters 98, May 2007, 190504-1-190504-4. [cited by applicant]
Rivest et al., “A method for obtaining digital signatures and public-key cryptosystems,” Communications of the ACM, Feb. 1978, 21(2):120-126. [cited by applicant]
Roetteler et al., “Quantum Resource Estimates for Computing Elliptic Curve Discrete Logarithms,” Proceedings of the 23rd International Conference on the Theory and Application of Cryptology and Information Security: Adv… [cited by applicant]
Schirokauer, “Discrete Logarithms and Local Units,” Philosophical Transactions of the Royal Society A, Nov. 1993, 345(1676):409-423. [cited by applicant]
Schonhage et al., “Schnelle Multiplikation großer Zahlen,” Computing 7, Sep. 1971, 281-292 (with English summary). [cited by applicant]
Schroeder et al., “DRAM Errors in the Wild: A Large-Scale Field Study,” ACM SIGMETRICS Performance Evaluation Review, Jun. 2009, 37, 193-204. [cited by applicant]
Shor, “Algorithms for quantum computation: Discrete logarithms and factoring,” Proceedings 35th Annual Symposium on Foundations of Computer Science, Nov. 1994, 124-134. [cited by applicant]
Smartcardfocus.com [online], “JavaCOS A22 dual interface Java card—150K,” available on or before Dec. 18, 2016, via Internet Archive: Wayback Machine URL <https://web.archive.org/web/20161218155914/http://www.smartcardf… [cited by applicant]
Van Meter et al., “Fast quantum modular exponentiation,” Physical Review A, May 2005, 71:052320-1-052320-12. [cited by applicant]
Van Meter, “Trading Classical For Quantum Computation Using Indirection,” Apr. 29, 2004, retrieved on Oct. 2, 2020, retrieved from URL <https://web.sfc.keio.ac.jp/˜rdv/quantum/publications/pay-the-exponential-full-inlin… [cited by applicant]
Van Oorschot et al., “On Diffie-Hellman Key Agreement with Short Exponents,” Proceedings of the International Conference on the Theory and Applications of Cryptographic Techniques, Advanced in Cryptology (EUROCRYPT 1996… [cited by applicant]
Vedral et al., “Quantum networks for elementary arithmetic operations,” Physical Review A, Jul. 1996, 147-153. [cited by applicant]
Wiebe et al., “Quantum arithmetic and numerical analysis using Repeat-Until-Success circuits,” CoRR, Submitted on Jun. 2014, arXiv:1406.2040v2, 32 pages. [cited by applicant]
Wikipedia.org [online], “Timeline of quantum computing,” available on or before Nov. 19, 2018, via Internet Archive: Wayback Machine URL <https://web.archive.org/web/20181119015658/https://en.wikipedia.org/wiki/Timeline… [cited by applicant]
Zalka, “Fast versions of Shor's quantum factoring algorithm,” https://arxiv.org/abs/quant-ph/9806084, Jun. 1998, 37 pages. [cited by applicant]
Zalka, “Shor's algorithm with fewer (pure) qubits,” https://arxiv.org/abs/quant-ph/0601097, Jan. 2006, 12 pages. [cited by applicant]
Office Action in Chinese Appln. No. 202080025632.7, mailed on Apr. 29, 2023, 27 pages (with English translation). [cited by applicant]
Office Action in Australian Appln. No. 2024201831, mailed on Dec. 12, 2024, 3 pages. [cited by applicant]
Extended European Search Report in European Appln. No. 24193979.2, mailed on Nov. 11, 2024, 9 pages. [cited by applicant]
Notice of Allowance in Australian Appln. No. 2024201831, mailed on Feb. 5, 2025, 3 pages. [cited by applicant]